A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
The vulnerability (CWE-77) consists of improper neutralization of special characters in input data passed to the IPSec VPN function, allowing injection of arbitrary system commands. The attack is possible remotely, without authentication and without user interaction, which classifies it as particularly dangerous (CVSS vector: AV:N/AC:L/PR:N/UI:N). Executed commands run in the system context with the highest ROOT privileges.
An attacker can take full control of the device, read and modify configuration, intercept network traffic, disrupt VPN tunnel operation, and use the device as an entry point to the internal network.
Apply patches available from the manufacturer according to references (https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf). Until firmware is updated, it is recommended to restrict access to the device management interface exclusively to trusted IP addresses and monitor anomalies in network traffic.
InHand Networks IR302 firmware V3.5.108 and earlier, IR305 firmware V1.0.118 and earlier, IR315 firmware V1.0.118 and earlier, IR615 firmware V1.0.118 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HInhandnetworks Ir302
HWInhandnetworksall versionsInhandnetworks Ir302 Firmware
OSInhandnetworks< 3.5.112Inhandnetworks Ir305
HWInhandnetworksall versionsInhandnetworks Ir305 Firmware
OSInhandnetworks< 1.0.121Inhandnetworks Ir315
HWInhandnetworksall versionsInhandnetworks Ir315 Firmware
OSInhandnetworks< 1.0.121Inhandnetworks Ir615
HWInhandnetworksall versionsInhandnetworks Ir615 Firmware
OSInhandnetworks< 1.0.121
Related vulnerabilities
Command injection w funkcji WireGuard VPN urządzeń InHand Networks
Command injection w funkcji ZeroTier VPN urządzeń InHand Networks
Command injection w firmware InHand Networks IR302/IR315/IR615 — dostęp ROOT
CSRF w routerze InHand Networks IR615 — zdalne wykonanie akcji administracyjnych
Command Injection w routerze InHand Networks IR615 via narzędzie ping